Impact
The Zephyr MQTT‑SN client contains a NULL pointer dereference in process_ping() when it removes a gateway that has failed to respond to keepalive PINGREQs. The list traversal macro returns no value, leaving the pointer NULL; subsequent code dereferences it during k_mem_slab_free(), corrupting the memory slab free list or triggering a kernel panic when pointer validation is enabled. The result is a crash or subtle memory corruption that denies service to the client. No attacker‑controlled data is written, and there is no additional privilege escalation.
Affected Systems
The flaw impacts the Zephyr Project’s Zephyr real‑time operating system, specifically the MQTT‑SN client implementation in subsys/net/lib/mqtt_sn. No specific release is listed; the patch can be found in commit bd21e954c36be105a374bbc090623810f1a17ee3 in the Zephyr source tree, so administrators must verify their Zephyr version and apply any available update that includes this fix.
Risk and Exploitability
The vulnerability scores a CVSS of 7.5; EPSS is 0.00336 (< 1%) and it is not listed in the CISA KEV catalog. The attack is remote: an attacker or compromised gateway can stop responding to MQTT‑SN PINGREQs over UDP, forcing the client to hit the defect. Because MQTT‑SN operates over UDP without authentication, any host on the network can trigger the denial of service, making the risk moderate to high for exposed devices.
OpenCVE Enrichment